McAfee released its annual “12 Scams of Christmas” list to educate the public on the most common scams that criminals use during the holiday season to take advantage of consumers as they shop on their digital devices. Cybercriminals leverage these scams to steal personal information, earn fast cash, and spread malware.

This year, fall holiday shopping sales are expected to soar to an estimated $602 billion. E-commerce sales are predicted to rise 15% compared to last year’s digital sales to more than $60 billion, with mcommerce comprising 16% of this number. Consumers should ensure that they are taking all precautions to protect the data saved on their devices. This is especially true for the 51% of US adults that bank online and 32% that use mobile banking.

“The potential for identity theft increases as consumers share personal information across multiple devices that are often under protected,” said Michelle Dennedy, vice president and chief privacy officer at McAfee. “Understanding criminals’ mindsets and being aware of how they try to take advantage of consumers can help ensure that we use our devices the way they were intended – to enhance our lives, not jeopardize them.”

McAfee has identified this year’s top “12 Scams of Christmas”:

1. Not-So-Merry Mobile Apps - Official-looking software for holiday shopping, including those that feature celebrity or company endorsements, could be malicious, designed to steal or send out your personal data. Criminals can redirect incoming calls and messages, offering them the chance to bypass two-step authentication systems where the second step involves sending a code to a mobile device.

2. Holiday Mobile SMS Scams - FakeInstaller tricks Android users into thinking it is a legitimate installer for an application and then quickly takes advantage of the unrestricted access to smartphones, sending SMS messages to premium rate numbers without the user’s consent.

3. Hot Holiday Gift Scams - Advertisements that offer deals on must-have items, such as PS4 or Xbox One, might be too good to be true. Clever crooks will post dangerous links, phony contests on social media sites, and send phishing emails to entice viewers to reveal personal information or download malware onto their devices.

4. Seasonal Travel Scams - Phony travel deal links and notifications are common, as are hackers waiting to steal your identity upon arrival. When logging into an infected PC with an email username and password, scammers can install keylogging spyware, keycatching hardware, and more. A hotel’s Wi-Fi may claim that you need to install software before using it and instead infect your computer with malware if you “agree.”

5. Dangerous E-Seasons Greetings - Legitimate-looking e-cards wishing friends “Season’s Greetings” can cause unsuspecting users to download “Merry Malware” such as a Trojan or other virus after clicking a link or opening an attachment.

6. Deceptive Online Games - Before your kids are glued to their newly downloaded games, be wary of the games’ sources. Many sites offering full-version downloads of Grand Theft Auto, for example, are often laden with malware, and integrated social media pages can expose gamers, too.

7. Shipping Notifications Shams - Phony shipping notifications can appear to be from a mailing service alerting you to an update on your shipment, when in reality, they are scams carrying malware and other harmful software designed to infect your computer or device.

8. Bogus Gift Cards - An easy go-to gift for the holidays, gift cards can be promoted via deceptive ads, especially on Facebook, Twitter, or other social sites, that claim to offer exclusive deals on gift cards or packages of cards and can lead consumers to purchase phony ones online.

9. Holiday SMiShing - During the holidays, SMiShing is commonly seen in gift card messages, where scammers pose as banks or credit card companies asking you to confirm information for “security purposes”. Some even include the first few digits of your credit card number in the SMS message to fool you into a false sense of safety.

10. Fake Charities - Donating to charities is common this time of year for many looking to help the less fortunate. However, cybercriminals capitalize on this generosity, especially during natural disaster events, and set up fake charity sites and pocket the donations.

11. Romance Scams - With so many niche dating sites now available to Internet users, it can be difficult to know exactly who the person is behind the screen. Many messages sent from an online friend can include phishing scams, where the person accesses your personal information such as usernames, passwords, and credit card details.

12. Phony E-Tailers - The convenience of online shopping does not go unnoticed by cyber scrooges. With so many people planning to shop online, scammers set up phony e-commerce sites to steal your money and personal data.

Spotlight

(IN)SECURE Magazine is a free digital security publication discussing some of the hottest information security topics. Learn about personal data bankruptcy and the cost of privacy, security and compliance, delivering digital security to a mobile world, and much more.

As ISPs, hosting providers and online enterprises around the world continue suffering the effects of DDoS attacks, often the discussions that follow are, “What is the best way to defend our networks and our customers against an attack?”

The code redirects visitors to another URL where the Fiesta exploit kit is hosted, which then tries to detect and exploit several vulnerabilities in various software. If it succeeds, the visitors are saddled with a banking Trojan.

Looking for an Android-based tablet for your child but don't know which one to choose? If you are concerned about the device's protection against random hackers, Bluebox Security has just released a review of the nine most popular Android tablet models aimed specifically at children.